10 Sources
[1]
Google warns that mass data theft hitting Salesloft AI agent has grown bigger
Google is advising users of the Salesloft Drift AI chat agent to consider all security tokens connected to the platform compromised following the discovery that unknown attackers used some of the credentials to access email from Google Workspace accounts. In response, Google has revoked the tokens
[2]
Attacks on Salesloft AI Chatbot Claim Another Victim: Cloudflare
Cloudflare Inc. is warning users of its technology to beef up their security after a hacker accessed the internet infrastructure company's customer support data. "Any information that a customer may have shared with Cloudflare in our support system -- including logs, tokens or passwords -- should
[3]
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. The ShinyHunters extortion group claims responsibility for these additional Salesforce
[4]
Google warns Salesloft breach impacted some Workspace accounts
Google now reports that the Salesloft Drift breach is larger than initially thought, warning that attackers also used stolen OAuth tokens to access a small number of Google Workspace email accounts in addition to stealing data from Salesforce instances. "Based on new information identified by
[5]
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations
Salesloft on Tuesday announced that it's taking Drift temporarily offline "in the very near future," as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication
[6]
Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data
A widespread data theft campaign has allowed hackers to breach sales automation platform Salesloft to steal OAuth and refresh tokens associated with the Drift artificial intelligence (AI) chat agent. The activity, assessed to be opportunistic in nature, has been attributed to a threat actor
[7]
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Revenue workflow platform Salesloft suffered a cyberattack which saw threat actors break in through a third-party and steal sensitive information. The company is using Drift, a conversational marketing and sales platform that uses live chat, chatbots, and AI, to engage visitors in real time,
[8]
Google warns Salesloft attack may have compromised Workspace accounts and Salesforce instances
Google disabled integrations and warned victims, in response The Salesloft cyberattack that happened earlier this week may have also compromised certain Google Workspace accounts, as well as Salesforce instances. This is according to Google's Threat Intelligence Group (GTIG), who published an
[9]
Breach of Salesloft Drift integration exposes data at Cloudflare, Zscaler and Palo Alto Networks - SiliconANGLE
Breach of Salesloft Drift integration exposes data at Cloudflare, Zscaler and Palo Alto Networks Cloudflare Inc., Zscaler Inc. and Palo Alto Networks Inc. have become the latest companies to be affected by the Salesloft breach, a widespread Salesforce Inc.-related security incident that has been
[10]
Google Warns of OAuth Attack on Salesforce Users
Google's Threat Intelligence Group (GTIG) issued an advisory on August 26 about a widespread data theft campaign targeting Salesforce customers that ran from August 8 to August 18. A rogue actor, identified as UNC6395, carried out this data theft by using compromised OAuth tokens linked to the
Share
Copy Link
A widespread data theft campaign targeting Salesloft's Drift AI chat agent has expanded beyond Salesforce, affecting hundreds of organizations and compromising OAuth tokens across multiple platforms.
A widespread data theft campaign targeting Salesloft's Drift AI chat agent has expanded beyond its initial scope, affecting hundreds of organizations and compromising OAuth tokens across multiple platforms. Initially reported as impacting only Salesforce integrations, the breach has now been found to affect other services, including Google Workspace
1
.
Source: Hacker News
Google's Threat Intelligence Group (GTIG) has revealed that the breach, which began as early as August 8, 2025, is more extensive than initially thought. The attack, attributed to a threat actor group known as UNC6395, has potentially impacted over 700 organizations
5
. Companies confirmed to be affected include Cloudflare, Google Workspace, PagerDuty, Palo Alto Networks, SpyCloud, Tanium, and Zscaler.
Source: SiliconANGLE
The attackers exploited compromised OAuth and refresh tokens associated with the Salesloft Drift AI chat agent to gain unauthorized access to customer Salesforce instances and other integrated platforms. Once inside, they executed queries against various Salesforce objects, including Cases, Accounts, Users, and Opportunities tables
3
.The primary objective of the attackers appears to be the theft of sensitive credentials, including:
This stolen data could potentially be used for further breaches of cloud accounts and infrastructure, likely for future extortion attempts
3
.Google has confirmed that the compromise extended to its Workspace accounts. On August 9, the threat actors used stolen OAuth tokens for the "Drift Email" integration to access emails from a small number of Google Workspace accounts directly integrated with Drift
4
.Related Stories
In response to the breach:
5
.5
.4
.Security experts and affected companies are advising the following actions:
1
.1
.4
.4
.4
.Salesloft has engaged cybersecurity firms Mandiant and Coalition to assist with the incident response and investigation
5
. As the situation continues to evolve, affected organizations are urged to remain vigilant and take proactive measures to secure their systems and data.Summarized by
Navi
[3]
[4]
02 Sept 2025•Technology

20 Apr 2026•Technology

26 Sept 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
